Versa Concerto Actuator Authentication Bypass Information Leak
Published May 21, 2025 ·Due Feb 12, 2026
9.2
CRITICALCVSS 4.0
EPSS 81.94%
Description
The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace logs.This issue is known to affect Concerto from 12.1.2 through 12.2.0. Additional versions may be vulnerable.
Affected products
-
- Version 12.1.2StatusaffectedConstraints<=12.2.0
- Version
- ≥ 11.4.0 · < 12.1.2
- 12.1.2
- 12.2.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:L/SA:N
1 other source (NVD) ▾
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
Date Added
Jan 22, 2026
Patch Due
Feb 12, 2026
Required Action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Jan 23, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2025–2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (23 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 81.94% (0.81940) | 99.64th | v5 (v2026.06.15) |
| Aug 22, 2026 | 81.94% (0.81940) | 99.62th | v5 (v2026.06.15) |
| Jun 15, 2026 | 83.38% (0.83381) | 99.64th | v5 (v2026.06.15) |
| Apr 17, 2026 | 71.58% (0.71578) | 98.73th | v4 (v2025.03.14) |
| Apr 14, 2026 | 73.73% (0.73729) | 98.82th | v4 (v2025.03.14) |
| Mar 26, 2026 | 75.05% (0.75054) | 98.86th | v4 (v2025.03.14) |
| Mar 21, 2026 | 56.46% (0.56463) | 98.09th | v4 (v2025.03.14) |
| Mar 17, 2026 | 62.38% (0.62383) | 98.34th | v4 (v2025.03.14) |
| Feb 18, 2026 | 56.99% (0.56994) | 98.08th | v4 (v2025.03.14) |
| Feb 12, 2026 | 58.55% (0.58547) | 98.15th | v4 (v2025.03.14) |
| Jan 30, 2026 | 45.82% (0.45819) | 97.52th | v4 (v2025.03.14) |
| Jan 26, 2026 | 47.46% (0.47460) | 97.60th | v4 (v2025.03.14) |
| Jan 25, 2026 | 54.54% (0.54542) | 97.95th | v4 (v2025.03.14) |
| Jan 24, 2026 | 52.96% (0.52959) | 97.87th | v4 (v2025.03.14) |
| Jan 23, 2026 | 49.99% (0.49989) | 97.73th | v4 (v2025.03.14) |
| Nov 14, 2025 | 8.69% (0.08685) | 92.10th | v4 (v2025.03.14) |
| Nov 9, 2025 | 9.94% (0.09939) | 92.70th | v4 (v2025.03.14) |
| Oct 17, 2025 | 7.42% (0.07421) | 91.28th | v4 (v2025.03.14) |
| Sep 20, 2025 | 8.44% (0.08440) | 92.00th | v4 (v2025.03.14) |
| Jul 19, 2025 | 6.14% (0.06144) | 90.37th | v4 (v2025.03.14) |
| Jun 15, 2025 | 7.51% (0.07512) | 91.30th | v4 (v2025.03.14) |
| May 23, 2025 | 3.42% (0.03417) | 86.85th | v4 (v2025.03.14) |
| May 22, 2025 | 0.05% (0.00054) | 17.21th | v4 (v2025.03.14) |
References (3)
- https://projectdiscovery.io/blog/versa-concerto-authentication-bypass-rce exploitmitigationThird Party Advisory
- https://security-portal.versa-networks.com/emailbulletins/6830f94328defa375486ff2e vendor-advisoryVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-34026 government-resourceUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| https://projectdiscovery.io/blog/versa-concerto-authentication-bypass-rce | exploitmitigationThird Party Advisory | |
| https://security-portal.versa-networks.com/emailbulletins/6830f94328defa375486ff2e | vendor-advisoryVendor Advisory | |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-34026 | government-resourceUS Government Resource |
Change history (0)
No recorded changes yet.